Security Content Versions Save

Splunk Security Content

v4.30.0

3 weeks ago

Release notes

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Macros Added

  • applocker
  • zscaler_proxy

Macros Updated

  • okta

Lookups Added

  • applockereventcodes

Other Updates

  • Added a new dashboard ESCU - AppLocker, Navigate to your Dashboards and search for "ESCU - AppLocker" to assist with auditing and monitoring Windows AppLocker events for your endpoints (Splunk Enterprise 9.x.x version and above only)

v4.26.0

2 months ago

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Macros Added

  • nginx_access_logs
  • suricata

Macros Updated

Lookups Added

Lookups Updated

  • remote_access_software

Playbooks Added

Playbooks Updated

Other Updates

  • Added a new script and a CI job to automatically upload the package to Splunkbase using a service account
  • Create SSA-Content-latest.tar.gz in the generate_ba CI job

v4.25.0

2 months ago

Release notes for ESCU v4.25.0

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Other Updates

  • Updated contentctl to output accurate providing technologies in savedsearches.conf

v4.24.0

2 months ago

Release notes for ESCUv4.24.0

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Playbooks Updated

Other Updates

v4.23.0

3 months ago

Release notes for ESCU v4.23.0

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Other Updates

  • Added a new input macro sourcetype="kube:container:falco"

Playbook Updates

  • Splunk Attack Analyzer Dynamic Analysis
  • Splunk Automated Email Investigation
  • Splunk Identifier Activity Analysis
  • Splunk Message Identifier Activity Analysis

v4.21.0

3 months ago

Release notes for ESCUv4.21.0

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Other Updates

  • Updated splunk_risky_command lookup with a new splunk_risky_command_20240122.csv file